Carta Trust Center | Powered by Conveyor
Carta
Quick Summary
One or more annual third-party audit(s)
Has a formal mobile device management (MDM) program
Annual third-party penetration testing
Has a disaster recovery plan
Has cyber insurance
Uses a centralized IAM solution (SSO) to manage employee access
Compliance
ISO 27001:2022
SOC 2 Type II
SOC 1 Type II
SIG
GDPR
CCPA
Featured Documents
Carta's Password Policy
Carta's Business Continuity Plan (External)
Carta SIG Core 2026
Carta ISO 27001 Certification
Carta ISO 27001 Certificate 2025-2028
Carta ISO 27001 - SOA v1.0 - March 2025
Bridge Letter for Carta's 2025 SOC 2 Reports
Avantia (now Carta Law) ISO 27001 Certification
2025 SOC 2 Type 2 Report for Capdesk
2025 SOC 2 Type 2 for ListAlpha (now CRM)
2025 SOC 2 Type 2 - Avantia Law (now Carta Law)
2025 SOC 1 Type 2 Report for Money Movement
2025 SOC 1 Type 1 Report for Money Movement
2025 Carta Audit Confirmations Service SOC 1 Type 1 Report
Use of AI at CARTA
Accelex (now LPPA) ISO 27001 Certification
2025 SOC 2 Type 2 for Sirvatus (now Loan Ops)
2025 Pen Test - Executive Report
2025 Carta Audit Confirmations Service SOC 1 Type 1 Report
2025 SOC 2 Type 2 Report for Carta Platform
2025 SOC 1 Type 2 Report for Fund Administration
2025 SOC 1 Type 2 Report for Cap Table
2025 SOC 1 Type 2 Report for Money Movement
2025 SOC 1 Type 2 Report for Fund Services
2025 SOC 1 Type 2 Report for Financial Reporting
Bridge Letter for Carta's 2025 SOC 1 Reports
Carta Data Processing Addendum
Documents & Knowledge Base FAQs
Documents27